Are these legit Files? Rawhide

Kevin Fenzi kevin at scrye.com
Tue Feb 24 18:41:51 UTC 2009


On Tue, 24 Feb 2009 12:28:17 +0000
Frank Murphy <frankly3d at gmail.com> wrote:

> RkHunter gives the following
> 
> Warning: Hidden file found: /usr/bin/.ssh-keyscan.hmac: ASCII text
> [09:16:37] Warning: Hidden file found: /usr/bin/.ssh-agent.hmac:
> ASCII text [09:16:37] Warning: Hidden file found: /usr/bin/.ssh.hmac:
> ASCII text [09:16:37] Warning: Hidden file
> found: /usr/bin/.ssh-add.hmac: ASCII text [09:16:37] Warning: Hidden
> file found: /usr/bin/.ssh-keygen.hmac: ASCII text [09:16:37] Warning:
> Hidden file found: /usr/sbin/.sshd.hmac: ASCII text
> 
> 
> Yum what provides */above(files) only gives the following
> 
> Filename    : /usr/bin/.ssh-keyscan.hmac
> 
> 
> 
> openssh-clients-5.1p1-7.fc11.i386 : An open source SSH client
> applications Repo        : installed
> Matched from:
> Filename    : /usr/bin/.ssh-keyscan.hmac
> 
> Wanted adivce before I ask on RKH list.

Yes, these are 'legit'. I need to update rkhunter to not flag them. 

It's part of the 'FIPS-150' standard. 

Personally I think these sig files are messy being in the dir that the
executables are in, but the standard apparently requires that. ;( 

> Frank

kevin
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 197 bytes
Desc: not available
URL: <http://listman.redhat.com/archives/fedora-list/attachments/20090224/a40eb5a2/attachment-0001.sig>


More information about the fedora-list mailing list